CCI-002912
CCI-002912 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if two forms of identification are required from [PE-02(02)_ODP; a list of acceptable forms of identification for visitor access to the facility where the system resides is defined] for visitor access to the facility where the system resides.
Validation Procedures
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing physical access authorizations; list of acceptable forms of identification for visitor access to the facility where the system resides; access authorization forms; access credentials; physical access control logs or records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with physical access authorization responsibilities; organizational personnel with physical access to the system facility; organizational personnel with information security responsibilities]. Test: [SELECT FROM: Organizational processes for physical access authorizations; mechanisms supporting and/or implementing physical access authorizations].